In partnership with leading academic institutions, we conducted a comprehensive measurement study of DNS security practices across the internet. This study analyzed over 10 million domains and 50,000 DNS resolvers to understand the current state of DNS security adoption.
DNSSEC Adoption
DNSSEC adoption has grown steadily but remains below optimal levels. Key findings include a 23.4% DNSSEC adoption rate for measured domains (up from 18.7% in 2024), significant regional variations (European domains at 31%, North American at 19%), and common misconfiguration issues affecting 12% of DNSSEC-enabled domains.
DNS over HTTPS (DoH) and DNS over TLS (DoT)
Encrypted DNS protocols show rapid growth. DoH usage increased 127% year-over-year, now accounting for 34% of measured DNS queries. Major browser implementations drove adoption significantly. DoT adoption lags behind DoH at 8% but shows steady growth in enterprise environments.
Security Implications
Our analysis revealed several security concerns: weak cryptographic parameters in 7% of DNSSEC implementations, DNS cache poisoning vulnerabilities in older resolver implementations, and lack of DNS security monitoring in 68% of surveyed organizations.
Recommendations
Based on our findings, we recommend organizations implement DNSSEC with proper key management practices, deploy DoH or DoT for privacy and security, regularly audit DNS configurations for misconfigurations, and monitor DNS traffic for security anomalies.